Skip to content

Commit

Permalink
netfilter: xt_recent: check for unsupported user space flags
Browse files Browse the repository at this point in the history
Signed-off-by: Tim Gardner <tim.gardner@canonical.com>
Signed-off-by: Patrick McHardy <kaber@trash.net>
  • Loading branch information
Tim Gardner authored and Patrick McHardy committed Mar 17, 2010
1 parent 0079c5a commit 606a9a0
Show file tree
Hide file tree
Showing 2 changed files with 8 additions and 0 deletions.
3 changes: 3 additions & 0 deletions include/linux/netfilter/xt_recent.h
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,9 @@ enum {
/* Only allowed with --rcheck and --update */
#define XT_RECENT_MODIFIERS (XT_RECENT_TTL|XT_RECENT_REAP)

#define XT_RECENT_VALID_FLAGS (XT_RECENT_CHECK|XT_RECENT_SET|XT_RECENT_UPDATE|\
XT_RECENT_REMOVE|XT_RECENT_TTL|XT_RECENT_REAP)

struct xt_recent_mtinfo {
__u32 seconds;
__u32 hit_count;
Expand Down
5 changes: 5 additions & 0 deletions net/netfilter/xt_recent.c
Original file line number Diff line number Diff line change
Expand Up @@ -319,6 +319,11 @@ static bool recent_mt_check(const struct xt_mtchk_param *par)
get_random_bytes(&hash_rnd, sizeof(hash_rnd));
hash_rnd_inited = true;
}
if (info->check_set & ~XT_RECENT_VALID_FLAGS) {
pr_info(KBUILD_MODNAME ": Unsupported user space flags "
"(%08x)\n", info->check_set);
return false;
}
if (hweight8(info->check_set &
(XT_RECENT_SET | XT_RECENT_REMOVE |
XT_RECENT_CHECK | XT_RECENT_UPDATE)) != 1)
Expand Down

0 comments on commit 606a9a0

Please sign in to comment.